JOBSEARCHER

Manager, Application Security, DevSecOps

KPMGWinter Park, FLL7 ManagerSeptember 15th, 2026
Overview In this role you drive AI-focused application security within KPMG’s Enterprise Security Services. You own the end-to-end AppSec evaluation and embed secure-by-design practices across DevSecOps, guiding teams through risk, controls, and governance. You’ll work with stakeholders to report on risk, tool coverage, and control maturity while staying ahead of the evolving AI threat landscape. This is an opportunity to shape secure AI adoption in a global, collaborative environment. Compensation / Benefitsmedical and dental plansvision coveragedisability and life insurance401(k) with matchpersonal well-being benefitspaid time off ResponsibilitiesEstablish and maintain AI-specific AppSec standards, evaluation frameworks, and security baselines for risks like data leakage and supply-chain threatsOwn the end-to-end AppSec evaluation process for AI tools and use cases, including intake, architectural assessments, data flows, and risk documentationAct as liaison between application teams and Information Security to embed AI AppSec requirements into DevSecOps processesProvide security consulting on secure AI design, integrations, operational models, and compensating controlsPresent evaluation findings, risk decisions, metrics, dashboards, and recommendations to technical and executive stakeholdersMaintain awareness of AI threat landscape and manage evaluation outcomes, approved tool lists, residual risks, and adoption of controlsUphold KPMG's respectful and courteous work environment Key requirementsMinimum six years of experience in application security, DevSecOps, secure software engineering, and SDLC governanceBachelor's degree preferred; high school diploma or GED requiredPreferred certifications: CISSP, CISM, GWAPT, GPEN, CEH, GWEB or equivalentStrong understanding of security standards and risk management in enterprise environmentsKnowledge of AI-related AppSec risks (prompt injection, data leakage, IP protection, supply-chain risks)Experience defining security standards, baselines, and evaluation criteria for large, global environmentsModerate to expert knowledge of cloud platforms (preference for Azure) and secure service designStrong written and verbal English communication for diverse audiencesAuthorized to work in the U.S. without visa sponsorship now or in the futureclear communicatorrelationship-builderproblem-solving orientationAppSec principlessecure coding standards (OWASP Top 10)risk management